5 ms·
> proprietary (with constant risk of malware, indeed) being proprietary has nothing to do with risk of malware, indeed
by StreamBright 5y ago
> proprietary (with constant risk of malware, indeed)
being proprietary has nothing to do with risk of malware, indeed
- defanor 5y agoTo be precise, I had in mind closed-source software: the software you can't inspect with reasonable effort/time before running, to ensure that it's not malicious. And especially in case of specialized software, that wasn't inspected by others either. Though these terms seem to be used interchangeably quite commonly [1], likely because of a strong correlation. [1] https://en.wikipedia.org/wiki/Proprietary_software https://en.wikipedia.org/wiki/Proprietary_software Edit: wording.
- karmoka 5y agoProprietary or open sourced doesn't matter much if you're not verifying the checksums of all the binaries that come per-installed on your system. If the majority of tech savvy people can't be bothered to do it, then average joe is doomed.
- ChrisLomont 5y ago>the software you can't inspect with reasonable effort/time before running, to ensure that it's not malicious. And you cannot do that on open source either. Both cases require a chain of trust, and empirically, neither is significantly more secure.
- emiliobumachar 5y agoFor a whole computer stack, that's true enough. Injecting malware in a single small widely distributed program and remaining stealthy for any length of time is a lot harder if it's open source.
- ChrisLomont 5y agoI don't think that's true. Care to pick some metric to check it? If anything, having source also makes it easier to auto scan for flaws at the source level and find holes. I know from CVEs that OS projects has a significant number of high profile long standing holes in it.
- squarefoot 5y ago> Injecting malware in a single small widely distributed program and remaining stealthy for any length of time is a lot harder if it's open source. Case in point, the famous Borland InterBase backdoor that went unnoticed for about 7 years and 3 versions of the software but was discovered in 8 months by one developer after Borland released InterBase as Open Source. https://www.zdnet.com/article/borland-interbase-backdoor-detected/ https://www.zdnet.com/article/borland-interbase-backdoor-det...
- StreamBright 5y ago> Injecting malware in a single small widely distributed program and remaining stealthy for any length of time is a lot harder if it's open source. Citation needed. On the other hand: https://en.wikipedia.org/wiki/Dual_EC_DRBG https://en.wikipedia.org/wiki/Dual_EC_DRBG
- defanor 5y agoI think the context somehow gets lost in this discussion. You indeed need a chain of trust in general, and can't inspect all the software alone even if it's FLOSS, but I'm talking about odd specialized programs shipped by hardware manufacturers (like the one TFA talks about) and similar one-off ones that come from an untrusted source: there's no trust there, no reliance on others inspecting it, but if you have the source code, it's often reasonable to read. Also occasionally desirable to fix or otherwise modify, to integrate into your overall system (that's what I tend to do pretty much each time when interacting with such sotfware+hardware, sometimes reverse engineering and reimplementing it, so maybe my view is a bit skewed). So FLOSS is good, closed source and proprietary is less trustworthy and less usable.
- ChrisLomont 5y ago>I'm talking about odd specialized programs shipped by hardware manufacturers (like the one TFA talks about In that case, open source rarely has even one possible replacement, so there's no comparison. >but if you have the source code, it's often reasonable to read As someone working in code daily, I disagree. I find lots of open source projects once you get out of the few big ones to be a massive mess of code. And most programs of much use are simply too big to do any sort of audit. I have lots of friends in open source - I doubt a single one has ever read over the source for an entire program to inspect. Have you honestly read over an entire open source program to check it? Or is this a myth that gets repeated but no one does it.... As to modification, I've reverse engineered many, many programs to add hooks and interoperability. It's not that terribly difficult once you've done a few and get to know how to do it. So sure, nice clean code is good. But open source software I find to be crappy for all but the few big uses. GIMP vs photoshop? No real good OS CAD, or finance, or comparing Octave to Mathematica? Buggy video editor of the week to DaVinci Resolve? Tax software? Inkscape vs AI? So as a result of lacking quality in OS, I prefer closed source solutions since paying for them gets me vastly better quality for a lot of things I want software for. And in the rare case I want to hack something, I still can and do. Open source is honestly a you-get-what-you-paid-for solution for most stuff.
- defanor 5y ago
- StreamBright 5y ago> the software you can't inspect with reasonable effort/time before running What was the last time you inspected any command or application you executed on your computer? How would you spot malicious code? Are you a security expert who has knowledge of all of the programming languages that have been used to write the apps you are running? You have absolutely unrealistic view on this subject. Btw. Apple and many companies have a trivial way of spotting malicious application by simple checksumming the executables.
- defanor 5y agoI'm surprised how this discussion turns out: didn't expect those bits to be controversial at all, and sibling comments make it sound like it's almost better to not have access to sources. > What was the last time you inspected any command or application you executed on your computer? A few months ago, and didn't run new code from untrusted sources since. > How would you spot malicious code? Are you a security expert who has knowledge of all of the programming languages that have been used to write the apps you are running? So far I haven't run into languages I can't read. Spotting malicious code could indeed be tricky, a subtle but critical vulnerability would easily evade quick skimming, just as malware is still possible even when it comes from a somewhat trusted source. But I'm more certain that a program does what it says it does after skimming its code. > Apple and many companies have a trivial way of spotting malicious application by simple checksumming the executables. That's how basic antiviruses work, not specific to Apple. They have to first add that checksum into a database, which isn't viable when we're talking about a small hardware manufacturer shipping their custom software to dozens of clients.
- StreamBright 5y agoIt took only 13 years to spot this in a FOSS project: https://linux.slashdot.org/story/22/01/25/2259214/major-linux-policykit-security-vulnerability-uncovered-pwnkit https://linux.slashdot.org/story/22/01/25/2259214/major-linu...